Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\] 'Shell' = '<Full path to file>'
- Windows Task Manager (Taskmgr)
- '34.##9.100.209':443
- DNS ASK google.com
- DNS ASK au######te.geo.opera.com
- DNS ASK se####.yahoo.com
- DNS ASK du###uckgo.com
- DNS ASK am##on.com
- DNS ASK bing.com
- DNS ASK bi##.#ikimedia.org
- DNS ASK en.###ipedia.org
- DNS ASK si#####ck2.opera.com
- DNS ASK re###.opera.com
- '%WINDIR%\syswow64\explorer.exe' http://pornoklik.com/